DLP/Data Security Engineer

ADTBoca Raton, FloridaOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Summary:

The DLP / Data Security Engineer is responsible for engineering, administering, and continuously improving enterprise controls that protect sensitive information across Microsoft 365, Google, email, endpoints, browsers, networks, and SaaS applications. This role serves as a technical owner for data loss prevention and related data security capabilities, translating business, privacy, legal, and regulatory requirements into practical policies, detections, enforcement actions, monitoring, exception processes, and response workflows.

The ideal candidate combines hands-on platform administration with strong troubleshooting, policy-tuning, automation, and communication skills. Success requires balancing strong protection with business usability, reducing false positives, measuring control effectiveness, and partnering across Security Engineering, Security Operations, IT, Legal, Privacy, Compliance, and application teams.

Duties and Responsibilities:

Microsoft Purview DLP and Information Protection

- Administer and maintain Microsoft Purview Data Loss Prevention policies across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and other supported locations.
- Configure and tune sensitive information types, classifiers, sensitivity labels, policy rules, user notifications, overrides, alerting, incident workflows, and scoped exceptions.
- Design policies that reduce unauthorized external sharing while preserving approved business workflows and maintaining clear, auditable exception paths.
- Investigate DLP alerts and user-reported issues, identify false positives and control gaps, and implement measured tuning based on risk and evidence.
- Maintain policy naming standards, administrative access, change records, testing procedures, operational documentation, metrics, and effectiveness reviews.

Google and Generative AI Data Security

- Administer Google Sensitive Data Protection and related Gemini Enterprise data security controls, including prompt, response, file, and connector protection where supported.
- Configure and tune protection for sensitive data, prompt injection, jailbreak attempts, and other approved AI security use cases.
- Validate DLP behavior through repeatable testing, troubleshoot inconsistent or overly broad detections, and document known limitations and user guidance.
- Coordinate logging and telemetry integration for Gemini and data protection events with BigQuery, SIEM, case management, and incident response workflows.
- Support governance of sanctioned and unsanctioned generative AI use, including discovery, policy enforcement, user warnings, blocking, and risk-based exceptions.

Network, SaaS, and CASB Data Protection

- Administer and expand network-level DLP, inline data inspection, and SaaS DLP or CASB controls across web traffic, cloud applications, APIs, collaboration platforms, and file-sharing services.
- Configure and tune data-in-motion and data-at-rest policies for sanctioned SaaS applications, external collaboration, cloud storage, uploads, downloads, copy-and-paste activity, and other exfiltration paths.
- Partner with Network Security and Cloud Security teams to align DLP enforcement with TLS inspection, secure web gateway, SASE, firewall, identity, and application control architectures.
- Evaluate overlapping capabilities across Purview, Google, Palo Alto, Slack, and other data security platforms to improve coverage and avoid conflicting or duplicate controls.
- Contribute to proof-of-value testing, product evaluations, architecture decisions, rollout plans, and operational readiness for new data security capabilities.

Email Security

- Administer email security controls that protect users and data from phishing, malicious content, impersonation, business email compromise, data leakage, and unauthorized forwarding or sharing.
- Tune policies, detections, allow lists, block lists, quarantine actions, user-reporting workflows, and exceptions while minimizing unnecessary disruption.
- Investigate email security incidents and collaborate with Security Operations on containment, remediation, threat hunting, and control improvements.
- Produce metrics and reporting on email threats, policy actions, coverage, false positives, user reporting, and outstanding risk.

Chrome Enterprise Browser Security

- Administer Chrome Enterprise browser security and data protection configuration, including managed policies, organizational unit scoping, trusted integrations, and controlled testing.
- Configure and evaluate browser-based controls for generative AI activity, file uploads and downloads, copy-and-paste restrictions, warnings, blocking, watermarking, and evidence capture where supported.
- Coordinate browser policy rollout with endpoint, identity, workstation engineering, and business stakeholders, using staged pilots and documented rollback plans.
- Monitor browser telemetry and policy effectiveness and integrate relevant security events into enterprise monitoring and response processes.

Operations, Governance, and Response

- Develop and maintain DLP response playbooks, operational runbooks, support procedures, architecture diagrams, policy inventories, exception documentation, and end-user guidance.
- Create dashboards and reports for technical teams and leadership, including policy actions, prevented events, alert trends, false-positive rates, coverage gaps, and remediation progress.
- Partner with Legal, Privacy, Compliance, Human Resources, Internal Audit, and business owners on investigations, evidence requests, policy decisions, and regulatory or contractual requirements.
- Participate in incident response involving suspected data exposure, insider risk, unauthorized sharing, credential leakage, or control bypass attempts.
- Automate repeatable administrative, reporting, triage, and policy-validation activities using APIs, scripting, SIEM/SOAR workflows, and cloud-native tooling.
- Stay current on data security, DLP, AI security, browser security, SaaS security, and email security threats and capabilities, and recommend pragmatic improvements.

Education and Experience:

- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
- Hands-on experience administering enterprise DLP, information protection, email security, CASB, SaaS security, endpoint, browser, or network security controls.
- Experience with Microsoft Purview DLP and Microsoft 365 workloads strongly preferred.
- Experience with Google Cloud Sensitive Data Protection, Gemini Enterprise security controls, Chrome Enterprise, or comparable technologies preferred.
- Experience with email security platforms, secure web gateways, SASE, firewalls, SaaS security platforms, and SIEM/SOAR integration preferred.
- Experience supporting regulated or sensitive data environments and working with privacy, compliance, legal, or audit stakeholders.
- Relevant certifications such as CISSP, CCSP, Microsoft Security, Compliance, and Identity credentials, Google Cloud security credentials, or GIAC certifications are preferred.

Skills and Knowledge:

- Strong understanding of data classification, sensitive information detection, context-based policy logic, exact data match concepts, labeling, encryption, access control, and data lifecycle protections.
- Ability to design layered controls across Microsoft 365, Google, email, endpoints, browsers, networks, and SaaS applications.
- Practical experience tuning detections to balance coverage, confidence, false positives, business impact, and enforceability.
- Working knowledge of identity and access management, conditional access, managed devices, browser management, TLS inspection, APIs, and cloud logging.
- Ability to analyze alerts and logs, identify root cause, document evidence, and translate technical findings into clear recommendations.
- Experience with PowerShell, Python, REST APIs, KQL/XQL, BigQuery, regular expressions, or similar query and automation technologies is a plus.
- Strong documentation, stakeholder communication, and project coordination skills.
- Ability to work independently, manage competing priorities, and collaborate effectively in a fast-paced security engineering environment.